Quantcast
Channel: SRX Services Gateway topics
Viewing all articles
Browse latest Browse all 3959

SRX240 not responding to SNMP Poll

$
0
0

I have a SRX 240 Cluster that cannot be polled via SNMP but it responds to SSH i have SNMP allowed under Interface and its vlans and also under routing instance. I checked the traffic logs and from what i can see is the policy that allows SSH also allows SNMP and SNMP is traffic is hitting the same policy but no response is received for SNMP. 

 

Session ID: 71710, Policy name: From_HOandRV/22, State: Active, Timeout: 1800, Valid
  In: 10.1.0.62/57327 --> 10.1.32.1/22;tcp, If: reth0.34, Pkts: 7, Bytes: 1472
  Out: 10.1.32.1/22 --> 10.1.0.62/57327;tcp, If: .local..4, Pkts: 7, Bytes: 2169

 

Session ID: 39397, Policy name: From_HOandRV/22, State: Active, Timeout: 8, Valid
  In: 10.1.0.62/57654 --> 10.1.32.1/161;udp, If: reth0.34, Pkts: 1, Bytes: 67
 Out: 10.1.32.1/161 --> 10.1.0.62/57654;udp, If: .local..4, Pkts: 0, Bytes: 0

 

 

Yes SNMP is allowed on all the interfaces traffic enters and leaves, i have enabled SNMP traceoptions and here's what i see

 

 snmpd[5093] >>> Get-Bulk-Request
 snmpd[5093] >>>  Source:      10.1.0.62
 snmpd[5093] >>>  Destination: 10.1.32.1
 snmpd[5093] >>>  Version:     SNMPv2
 snmpd[5093] >>>  Request_id:  0x5093
 snmpd[5093] >>>  Community:   abcxvzxd  ----- the correct SNMP V2 String from the SNMP server
 snmpd[5093] >>>  Non-repeaters:   0
 snmpd[5093] >>>  Max-repetitions: 20
snmpd[5093] >>>   OID  : std
snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
 snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
 snmpd[5093] >>> Get-Bulk-Request
 snmpd[5093] >>>  Source:      10.1.0.62
 snmpd[5093] >>>  Destination: 10.1.32.1
 snmpd[5093] >>>  Version:     SNMPv2
snmpd[5093] >>>  Request_id:  0x5093
 snmpd[5093] >>>  Community:   zxd ------- it removd part of the snmp string and only took the last few characters
 snmpd[5093] >>>  Non-repeaters:   0
 snmpd[5093] >>>  Max-repetitions: 20
 snmpd[5093] >>>   OID  : std
 snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
 SNMPD_AUTH_FAILURE: nsa_log_community: unauthorized SNMP community from 10.1.0.62 to 10.1.32.1 ( abcxvzxd)  --- then SRX classifies the entire string as unauthorized community string. Any help to resolve this issue would be appritiated.

 

 


Viewing all articles
Browse latest Browse all 3959

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>